...
首页> 外文期刊>Future generation computer systems >MAPE-K/MAPE-SAC: An interaction framework for adaptive systems with security assurance cases
【24h】

MAPE-K/MAPE-SAC: An interaction framework for adaptive systems with security assurance cases

机译:MAPE-K / MAPE-SAC:具有安全保障案件的自适应系统的交互框架

获取原文
获取原文并翻译 | 示例
           

摘要

Security certification establishes that a given system satisfies properties and constraints as specified in the system security profile. Mechanisms and techniques have been developed to assess if and how well the system complies with the properties, thereby providing a degree of confidence in the security certification. Generally, certification of security controls defined by NIST SP800-53 is performed at design time to provide confidence in a system's trustworthiness to achieve the organization's mission and business requirements. Assuring confidence in a self-adaptive system's security profile is challenging when both functional and security conditions may change at run time. Static security solutions are insufficient, given that dynamic application of defense mechanisms often needs to dynamically adapt security functionality at run time as part of self-protection. This security adaptation may hinder maintaining functional constraints or vice versa. In addition, adaptation capabilities may give rise to the need for dynamic certification, which can be a difficult procedure given the complexity of the security dependencies. Confidence in an information system's compliance with security constraints can be expressed using security assurance cases (SACs). NIST security controls are defined with a hierarchical structure that makes them amenable to being specified in terms of SACs. A collection of SACs for related security controls form a network that can be used to measure the confidence of security compliance through certification-based evidence. Once the system is deployed, environmental and functional uncertainties may require the coordination of functional and security adaptations. This paper introduces the MAPE-SAC, a security-focused feedback control loop, and its interaction with a MAPE-K, function and performance-focused control loop, to dynamically manage run-time adaptations in response to changes in functional and security conditions. We illustrate the use of both control loops and their interaction with an example of two independent systems that need to cooperate to facilitate autonomous search and rescue in the aftermath of a natural disaster.
机译:安全认证确定给定系统满足系统安全性配置文件中指定的属性和约束。已经开发了机制和技术来评估系统符合性质的影响,从而在安全认证方面提供了一定程度的信心。通常,NIST SP800-53定义的安全控制认证在设计时进行了在设计时,为实现组织的使命和业务需求提供信心。当功能和安全条件可能在运行时可能会发生变化时,对自适应系统的安全配置文件确保对自适应系统的安全性有挑战性。静态安全解决方案不足,因为防御机制的动态应用程序通常需要在运行时动态适应安全功能,作为自我保护的一部分。这种安全适应可能阻碍维护功能约束,反之亦然。此外,适应能力可能会导致动态认证的需要,这可能是给定安全依赖性的复杂性的困难程序。可以使用安全保障案例(SACS)表达对信息系统的信心与安全约束的遵守。 NIST安全控件由分层结构定义,使它们能够在SAC方面进行。用于相关安全控制的SAC的集合形成了一种可用于通过基于认证的证据来衡量安全合规性的信心。部署系统后,环境和功能不确定性可能需要协调功能和安全自适应。本文介绍了MAPE-SAC,一种可信的反馈控制循环及其与MAPE-K,功能和焦点控制回路的交互,以响应于功能和安全条件的变化而动态管理运行时调整。我们说明了控制循环和它们的互动,与需要合作的两个独立系统的互动,以便在自然灾害的后果中促进自主搜查和救援。

著录项

  • 来源
    《Future generation computer systems》 |2020年第8期|197-209|共13页
  • 作者单位

    Tandy School of Computer Science University of Tulsa Tulsa OK 74104 USA;

    Tandy School of Computer Science University of Tulsa Tulsa OK 74104 USA;

    Tandy School of Computer Science University of Tulsa Tulsa OK 74104 USA;

    Tandy School of Computer Science University of Tulsa Tulsa OK 74104 USA;

    Department of Computer Science & Engineering Michigan State University East Lansing MI 48824 USA;

    Department of Computer Science & Engineering Michigan State University East Lansing MI 48824 USA;

    Department of Computer Science & Engineering Michigan State University East Lansing MI 48824 USA;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Security assurance cases; Self-adaptation; Security certification; MAPE loop;

    机译:安全保障案件;自适应;安全认证;mape循环;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号